CVE-2023-41892
10.0
CRITICAL · CVSS 3.1 · EPSS 94.2% (pctl 100)
Patch early
EPSS 94.2% — above the 10% action threshold.
Description
Craft CMS is a platform for creating digital experiences. This is a high-impact, low-complexity attack vector. Users running Craft installations before 4.4.15 are encouraged to update to at least that version to mitigate the issue. This issue has been fixed in Craft CMS 4.4.15.
Scoring
| CVSS | 10.0 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L |
| EPSS | 94.22% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-94 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2023-09-13 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| craftcms | craft cms |
References
- http://packetstormsecurity.com/files/176303/Craft-CMS-4.4.14-Remote-Code-Execution.html
- https://github.com/craftcms/cms/blob/develop/CHANGELOG.md#4415---2023-07-03-critical
- https://github.com/craftcms/cms/commit/7359d18d46389ffac86c2af1e0cd59e37c298857
- https://github.com/craftcms/cms/commit/a270b928f3d34ad3bd953b81c304424edd57355e
- https://github.com/craftcms/cms/commit/c0a37e15cc925c473e60e27fe64054993b867ac1
- https://github.com/craftcms/cms/commit/c0a37e15cc925c473e60e27fe64054993b867ac1#diff-47dd43d86f85161944dfcce2e41d31955c4184672d9bd9d82b948c6b01b86476
- https://github.com/craftcms/cms/security/advisories/GHSA-4w8r-3xrw-v25g
- http://packetstormsecurity.com/files/176303/Craft-CMS-4.4.14-Remote-Code-Execution.html
- https://github.com/craftcms/cms/blob/develop/CHANGELOG.md#4415---2023-07-03-critical
- https://github.com/craftcms/cms/commit/7359d18d46389ffac86c2af1e0cd59e37c298857
- https://github.com/craftcms/cms/commit/a270b928f3d34ad3bd953b81c304424edd57355e
- https://github.com/craftcms/cms/commit/c0a37e15cc925c473e60e27fe64054993b867ac1
- https://github.com/craftcms/cms/commit/c0a37e15cc925c473e60e27fe64054993b867ac1#diff-47dd43d86f85161944dfcce2e41d31955c4184672d9bd9d82b948c6b01b86476
- https://github.com/craftcms/cms/security/advisories/GHSA-4w8r-3xrw-v25g
→ the Explorer · watch your stack · NVD